Privacy Not A Crime
668 subscribers
196 photos
20 videos
234 links
🔐 Take control of your digital freedom.

Curated tools and expert insights on Privacy, Cybersecurity and OSINT. Actionable guides to protect your data and communications.

Defend your rights online. 🔰
Download Telegram
🔍 6 Search engines that find the internet that Google forgot

While giants like Google dominate the digital landscape, they often filter out smaller, niche, or older sites in favor of SEO-optimized content and commercial interests. This creates a blind spot where valuable information gets lost.

Fortunately, there are alternative search engines dedicated to uncovering these hidden corners of the web while respecting user privacy. Unlike their mainstream counterparts, they do not track your history or build profiles for advertising.

🌐 Discovering the forgotten web

The modern internet is vast, yet much of it remains invisible to standard algorithms. Large search engines prioritize relevance based on popularity and monetization potential, effectively burying independent blogs, academic archives, and legacy websites. The six search engines highlighted below aim to reverse this trend, offering unique indexing strategies that cater to researchers, privacy advocates, and anyone tired of algorithmic echo chambers.

They focus on raw data, human-curated results, and the preservation of digital diversity.

💸 Search engines designed for depth and privacy

Marginalia Search stands out by specifically targeting sites that lack professional design but hold valuable content. It ignores SEO tricks and visual polish, focusing instead on the text and structure of pages that are often overlooked. It is an excellent choice for finding genuine discussions and obscure resources without the noise of commercial spam.

Wiby takes a different approach by indexing only small websites. It excludes large corporations and popular domains, ensuring that the results come from individual creators and niche communities. This makes it a treasure trove for authentic voices that would otherwise be drowned out by major media outlets.

Million Short allows users to remove the top 100, 1,000, or even 10 million most popular sites from search results. By filtering out the giants, it reveals the long tail of the internet, showing you what exists beyond the first page of Google. It is a powerful way to bypass the saturation of mainstream content.

Search My Site is a specialized utility that lets you search within specific domains or collections of sites. While not a general crawler, it empowers users to curate their own search environment, ensuring that results come exclusively from trusted sources or specific interest groups they define.

Mwmbl operates as a community-driven, open-source search engine. It aims to create a decentralized alternative to corporate search, where the index is built and maintained by volunteers. This model ensures transparency and prevents the centralization of information control.

Mojeek offers a completely independent crawl of the web, distinct from the indexes used by Google or Bing. It does not track users or store personal data, providing a truly private search experience. Its results are generated solely from its own database, ensuring unbiased and diverse outcomes.

These search engines prove that the internet can still be explored freely, without the constraints of massive algorithms or invasive tracking. Whether you are looking for deep research material or simply want to escape the filter bubble, they offer a refreshing alternative. If privacy matters to you, switching to one of these options is a simple but effective step.

Combine them with a good VPN and a tracker-blocking extension to further reduce your digital footprint.

😊 If you enjoyed the article share it with your friends and follow us.

#SearchEngines #PrivacyFirst #NoTracking #OpenWeb #AltSearch

@PrivacyNotACrime 🗽 ⌨️ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
1✍6👀42111
👁‍🗨 Telegram OSINT tools guide

Telegram keeps growing as a go-to platform for communication, and with that growth comes a whole ecosystem of open source intelligence tools designed to dig into publicly available data.

Whether you are a journalist tracing misinformation, a researcher mapping networks, or a security analyst profiling threats, Telegram offers a surprisingly rich surface area for investigation. The toolkit available covers everything from simple search engines to Maltego transforms that plug directly into professional workflows.

📱 Search engines built for Telegram

Each of these serves a slightly different purpose, so knowing which one to reach for depends on what you are looking for:

Telegago — Works like a customized Google that only indexes public Telegram content from t.me and telegram.me domains. Supports keyword searches, exact phrases, and date range filtering.

TGStat — Focuses on channel analytics, subscriber growth, and citation indexes. Ideal when you need to understand the reach and influence of a particular channel.

Telegramchannels — Maintains categorized directories of public channels, bots, and groups. Good for discovery by topic.

TelegramDB — Allows searching across channels, groups, bots, and users simultaneously from one interface.

Commentgram CSE — Indexes comments and replies inside channels, which often contain valuable intelligence that gets overlooked.

Lyzem — Offers category-filtered channel discovery with slightly different indexing than Telegago.

Telegram Nearby Map — Surfaces channels and groups tied to specific geographic coordinates. Particularly useful in investigations involving physical locations.

🔘 Bots that do the heavy lifting

Telegram bots are probably the quickest way to start pulling intelligence without installing anything. They cover a wide range of functions, so here is a breakdown organized by what they actually do:

Message and media search:

@very_new_tgscan_bot — Searches indexed channels for messages and media across the platform.

Searchfirmbot — Handles channel and message discovery by keyword.

Account metadata:

Creationdatebot — Reveals when a Telegram account was registered. Surprisingly useful in building timelines.

Usernametoidbot — Converts usernames into unique numeric identifiers.

@RegDatezbot — Alternative registration date lookup tool.

Identity and cross-platform tracing:

Maigret OSINT bot — Takes a username and checks it across multiple platforms simultaneously.

EyeTON — Performs deep profile analysis on Telegram accounts.

UsInfoBot — Aggregates available user information into a single response.

Domain and infrastructure:

WhoisDomBot — Brings WHOIS domain lookups directly into the chat.

OpenDataUABot — Pulls Ukrainian business registry data tied to users or entities.

Audio and translation:

VoiceMsgBot — Converts voice messages into text, opening up audio content for analysis.

Transcriberbot — Audio transcription with broader language support.

YTranslateBot — Handles content translation when language barriers come up.

🕸 Scrapers and collection frameworks

When you need to go beyond casual searching, scraping tools let you pull structured data at scale. These require more setup but deliver significantly more depth:

Telepathy — Developed by Jordan Wildon. Archives entire chat histories including replies, media, and reactions. Generates member lists of up to 5,000 users, maps forwarded message chains, looks up users by location, and exports everything to CSV. Runs from the command line and requires a Telegram API key.

TeleTracker — Provides channel activity monitoring and change tracking through simple Python scripts.

TgramSearch — Offers targeted keyword search capabilities across multiple channels.

TeleGraphite — Focuses on structured channel data extraction for further analysis.

📃 Check the full list here

😊 If you enjoyed the article share it with your friends and follow us.

#Telegram #OSINT #PrivacyTools #CyberSecurity #Scrapers

@PrivacyNotACrime 🗽 ⌨️ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
318🥰6👀5✍111
🇪🇸 Spain sees 81% surge in online shopping scams

Online fraud is on the rise across Spain, with a staggering 81% increase in scams related to fake online stores reported in recent months. Cybercriminals are increasingly exploiting the popularity of e-commerce, creating convincing but fraudulent websites to steal money and personal data from unsuspecting shoppers.

💡 How the scams work

These fraudulent sites often mimic legitimate retailers, offering popular products at unrealistically low prices. Once victims place an order and make a payment, they either receive nothing at all or a counterfeit item. In many cases, the scammers also harvest credit card details and personal information for further identity theft or financial fraud.

The surge coincides with peak shopping periods, including seasonal sales and holiday promotions, when consumers are more likely to browse multiple online shops looking for deals. Attackers leverage social media ads, search engine optimization tricks, and phishing emails to drive traffic to their fake storefronts.

🚩 Red flags to watch out for

Identifying a scam store isn't always straightforward, but several warning signs can help. Prices that seem too good to be true are often the first clue. Missing or generic contact information, lack of secure payment methods, poor grammar, and unprofessional design are also common indicators. Pay attention to domain names that slightly alter well-known brands to trick users into trusting the site.

🛡 How to stay safe while shopping online

To minimize your risk, stick to trusted retailers with verified reputations. Always check for HTTPS encryption in the URL bar, and avoid entering payment details on sites that lack proper security certificates. Use credit cards or payment services that offer buyer protection, and never share sensitive information via email or unsolicited messages.

A couple of extra checks can go a long way: look at the domain registration date of the website. Fake stores are often freshly created, so if a shop claims years of experience but the domain was registered just weeks ago, that's a major red flag. Also, pay attention to customer reviews and their age. Scam sites may post generic five-star ratings, but genuine stores usually have reviews spread out over time with real, detailed feedback. A page flooded with glowing reviews all posted within the same few days should raise suspicion.

If you suspect you've been targeted, report the incident to local authorities and your bank immediately. Many countries have dedicated cybercrime units that track and investigate such fraud.

😊 Follow us to stay informed about the latest threats and protect yourself.

#EcommerceScams #SpainAlert #FakeShops #CyberSafety #OnlineFraud

@PrivacyNotACrime 🗽 ⌨️ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
✍5👀51
😡 Reqlore: Local web application pentesting suite

Security researchers need tools that balance power with privacy when testing web applications. Reqlore emerges as a comprehensive local pentesting platform offering proxy, repeater, intruder, decoder, and scanner capabilities in a unified interface that serves as an accessible alternative to commercial solutions like Burp Suite.

🤯 Core modules for complete testing

The suite operates through distinct panels handling different aspects of security work. The Proxy module intercepts traffic between browser and target application while History maintains complete request logs for analysis. Repeater enables manual refinement and replay of individual HTTP requests, and Intruder automates payload injection across multiple parameters. Meanwhile the Scanner component identifies known vulnerability patterns and Decoder handles various encoding formats for proper payload preparation.

⚙️ Multiple request engines for flexibility

Reqlore stands out with six different request engine options giving operators flexibility in how they interact with targets. Users can select between httpx, raw, h3 for HTTP/3 testing, and curl-cffi backends depending on specific requirements. This modularity enables bypassing certain network restrictions or testing protocol-specific behaviors that single-engine tools simply cannot address effectively.

🟠 Installation options and security

Multiple installation approaches support different workflows including Docker deployment and manual Python setup. Containerized environments keep configuration files in a dedicated data directory while authentication relies on argon2id password hashing that never stores plaintext credentials on disk. Debian and Ubuntu users benefit from an installation script handling dependency management automatically.

🛡 Defensive measures against reconnaissance

Tools like Reqlore highlight the importance of robust defensive postures for web applications. Organizations should configure Web Application Firewalls to detect rapid-fire probing patterns, hide administrative interfaces behind strong authentication and IP whitelisting, enable comprehensive logging with real-time alerting for suspicious request volumes, and enforce rate limiting on all public-facing endpoints to slow automated enumeration attempts.

🔘 Built-in accessibility considerations

Unlike many security tools overlooking inclusive design, Reqlore integrates accessibility directly into its architecture following WCAG 2.2 AA standards with AAA-strict patterns. The interface ensures compatibility with screen readers including NVDA, JAWS, Orca and VoiceOver, making professional security testing accessible to practitioners with disabilities who previously faced barriers using traditional platforms.

🐱 Check the repository at GitHub

😊 If you enjoyed the article share it with your friends and follow us.

#CyberSecurity #PenTesting #BugBounty #InfoSec #WebSecurity

@PrivacyNotACrime 🗽 ⌨️ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
5✍7👀411
📄 Archive.ph: Your digital time capsule for web pages

How many times have you shared a link only to find out later that the content was edited or simply disappeared? We've all been there. Archive.ph solves exactly that problem by taking a permanent snapshot of any webpage, preserving both its text and visual layout exactly as it appeared at a given moment. No edits, no deletions, no surprises.

⚙️ How does it actually work

The concept is simple but powerful. When you paste a URL into Archive.ph, the service downloads the page content along with a graphical copy for maximum accuracy. What makes it especially useful is that it strips out all active scripts, pop-ups, and interactive elements from the saved version.

This means the archived page is not only permanent but also completely safe to open, since there's no hidden malware or trackers lurking behind it. You get a short, clean link to an unalterable record.

🥰 Why privacy folks love it

Here's where things get interesting. When you view a page through Archive.ph, you never actually connect to the original server. The content lives on their infrastructure, which means the target site can't log your IP, track your behavior, or plant cookies on you. For anyone who cares about digital privacy, that's a big deal. You can access content that might be geoblocked in your region without revealing your real location, and since all dynamic scripts are removed, there's no risk of client-side exploits running in the background.

🌍 Real-world scenarios where it shines

Think about a journalist needing to preserve a politician's tweet before it gets deleted under pressure. Or a lawyer capturing terms of service right before a company quietly rewrites them. Even in everyday life, it comes handy more than you'd expect: saving a job listing before it's taken down, archiving a rental ad that seems too good to be true, or keeping a record of a forum post that could vanish overnight.

🛡 Staying safe while using it

Even though Archive.ph gives you a script-free, sanitized view of any page, common sense still applies. Always double-check the URL before archiving to make sure you're capturing the right content. Keep in mind that the original site remains untouched, so don't let your guard down if you later visit the live version. And for extra privacy, consider pairing it with a VPN so not even your connection to the archive itself can be traced back to you.

💸 Two domains are available:

🖥 https://archive.ph
🖥 https://archive.today

😊 If you enjoyed the article share it with your friends and follow us.

#Cybersecurity #DigitalPrivacy #WebArchives #InfoSec #OnlineSafety

@PrivacyNotACrime 🗽 ⌨️ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
✍6👀321
🇺🇸 US declares emergency after cyberattack hits police systems

The United States has officially declared a state of emergency following a severe cyberattack targeting local police infrastructure. The incident has disrupted critical communication channels and forced authorities to revert to manual operations while security teams work to isolate the breach.

⚠️ FBI steps in urgently

In response to the escalating situation, the city council has formally requested immediate intervention from the Federal Bureau of Investigation (FBI).
Federal agents are now leading the forensic analysis to identify the threat actors and determine the extent of the compromise.

This move underscores the growing reliance on federal resources when local digital defenses are overwhelmed.

🟪 Risks of centralized digital dependency

This event highlights a critical vulnerability in modern municipal governance: when essential city services depend on a single digital infrastructure, a failure in one component can cascade rapidly beyond just computers. From dispatch systems to evidence databases, the interconnected nature of these networks means that a localized malware infection can paralyze an entire department's ability to respond to public safety needs. Experts warn that without redundant, air-gapped backup systems, such attacks pose a direct threat to community safety.

😊 Follow us to stay informed about the latest threats and protect yourself.

#CyberEmergency #PoliceHack #DigitalSafety #FBIInvestigation #Critical

@PrivacyNotACrime 🗽 ⌨️ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
🤔5😁22
📱 Android security bypassed via malicious SIM card commands

Think the SIM card in your phone is just for your carrier? Think again. Behind that small chip lies a miniature computer capable of sending commands directly to your device's modem.

In the wrong hands, this can lead to serious trouble, even on a locked Android phone.

💩 An 80s standard with modern consequences

The issue stems from the AT command protocol, a system originally designed in the 1980s for dial-up modems. Decades later, millions of smartphones still rely on this legacy infrastructure. Security researchers have discovered how a maliciously crafted SIM can exploit this inherent trust, injecting commands that bypass Android's lock screen protections. The implications are severe: unauthorized access to messages, location tracking, and network manipulation can occur without ever needing your passcode.

☠️ What makes the attack possible

The vulnerability lies within the SIM Application Toolkit, a legitimate feature intended to allow your SIM to interact with phone menus for tasks like checking your balance. However, when developers fail to properly validate these interactions, the toolkit transforms into a backdoor.

Since most modems are designed to inherently trust commands originating from the SIM, a compromised card can execute harmful operations immediately. This means anyone with physical access to your device or someone who convinces you to swap in a fake SIM could gain unexpected control over your communications.

❤️ Protecting yourself without panic

Fortunately, manufacturers are gradually rolling out patches, though the vast number of affected devices means many remain exposed. You can significantly reduce your risk by obtaining SIM cards exclusively from official carriers and avoiding unknown sources.

Keeping your firmware updated is crucial, particularly regarding modem security. If your phone supports eSIM, switching to it eliminates the physical slot entirely, effectively cutting off this attack vector. Additionally, if you notice unusual behavior such as random network disconnections or suspicious text activity, investigate immediately.

😊 Follow us to stay informed about the latest threats and protect yourself.

#AndroidSecurity #SIMVulnerability #MobilePrivacy #CyberThreats #TechSafety

@PrivacyNotACrime🗽 ⌨️ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
👌7👀31
🇪🇸 Spanish hacker Gil exposes NATO and SBU intelligence data

Enrique Arias Gil, also known as "Desinformador Ruso", is a Spanish IT specialist currently residing in Russia, claims to have uncovered the personal data of 400 intelligence officers from Ukraine and Spain, many of whom are linked to NATO, the CIA, and the SBU. This revelation sends shockwaves through western security circles, highlighting vulnerabilities in how sensitive personnel information is stored and protected.

🌟 A three-month operation with global implications

According to Gil, the data collection effort took approximately three months of dedicated work. The compromised information includes high-ranking officials such as brigadier generals, colonels, and lieutenant colonels. One particularly symbolic figure mentioned is a lieutenant colonel from the Spanish Armed Forces Intelligence Center, reportedly connected to NATO operations, Ukraine, and cognitive warfare initiatives. Beyond military ranks, Gil also obtained photographs and personal details of over 1,000 Spanish police officers.

🎉 The geopolitical chessboard

Gil received political asylum in Russia in February and has since integrated into the Russian academic sector, teaching at two higher education institutions. He currently holds a temporary visa but aims to secure permanent residency within five to six months, eventually seeking citizenship. His case illustrates a growing trend where nations actively recruit foreign cybersecurity experts, regardless of their controversial backgrounds or legal status elsewhere.

👮‍♂️ Charges and international pursuit

Spanish authorities have accused Gil of espionage, sabotage, cyberterrorism, and data theft in the interest of Russia. He claims to be the most wanted person by Europol. While his actions have sparked outrage in Madrid, his asylum in Moscow underscores the complex intersection of cybersecurity, geopolitics, and intellectual talent migration.

😊 Follow us to stay informed about the latest threats and protect yourself.

#CyberEspionage #DataLeak #NATO #Europol #InfoSec

@PrivacyNotACrime 🗽 ⌨️ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
👀12✍10🤔9🙈5😁4👌31
This media is not supported in your browser
VIEW IN TELEGRAM
🇮🇱 Mossad sends data instead of stealing it: a real espionage success?

Imagine you're a spy agency with billions in budget, fancy surveillance tools, and decades of operational experience. Now imagine you try to hack a lawyer's phone and somehow manage to send him your entire contact list instead of stealing anything. Welcome to the world of modern cyberespionage, where sometimes the biggest threat to national security is a simple misconfigured script.

⚠️ The operation that backfired harder than expected

The story comes from Juan Branco, one of only twelve lawyers in France representing Palestinian victims. According to him, Mossad's attempt to extract data from his phone resulted in the exact opposite: a massive push of sensitive information onto his device. And not just any contacts. We're talking phone numbers for Elon Musk, Sam Altman, and essentially every top political, judicial, and intelligence figure in Israel.

It's like trying to rob a house and accidentally leaving your wallet full of addresses and passwords on the doorstep. The irony here is almost too perfect: a lawyer defending people who've been surveilled ends up receiving the surveillance database itself. Bravo, truly professional work.

❔ Questions nobody asked but everyone should

This blunder raises more questions than answers. How does a sophisticated operation designed for covert extraction flip into a mass data delivery system? What kind of quality control exists before deploying tools that could accidentally expose an entire intelligence network to its enemies?.

For Branco, the situation is legally messy. Possessing classified Israeli contacts could complicate his cases or endanger sources. For the individuals whose numbers were leaked, including tech giants and government officials, the risks of doxxing and harassment are real. And for Mossad? Well, let's just say their reputation took a hit that no amount of denials will fully fix.

😊 Follow us to stay informed about the latest threats and protect yourself.

#Mossad #SpyBlunder #DataLeak #CyberSecurity #IntelOps

@PrivacyNotACrime 🗽 ⌨️ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
🤣10👀5😁3
🌐 FirewallFalcon Manager: When free VPN tools hide a dangerous secret

Over 650 servers caught in a coordinated campaign, all traced back to a single open-source utility that thousands trusted blindly.

FirewallFalcon Manager presented itself as a handy, community-driven solution for managing VPN servers on Linux and here is the worst part: it actually worked. It delivered every feature it promised. But behind that polished functionality lurked a quietly modified component that turned it into a remote control for attackers.

🌟 A supply chain attack disguised as convenience

The malicious operation was elegant in its simplicity. Perpetrators took the legitimate tool and surgically replaced its subscription verification mechanism with a rogue module granting them administrative authority over every deployment. Instead of authenticating users, the tampered code opened a hidden channel allowing attackers to intercept, redirect, and manipulate all client traffic flowing through affected servers. Since the rest of the application continued performing exactly as advertised, administrators had almost no visible clue that something was terribly wrong underneath.

ℹ️ What makes this case particularly troubling

This is not the typical scenario where a shady tool tricks inexperienced users into installing malware.

FirewallFalcon Manager looked legitimate, felt legitimate, and behaved legitimately. That is precisely what supply chain attacks thrive on. By poisoning a trusted distribution channel, operators managed to compromise a vast network of servers without exploiting a single vulnerability in the traditional sense. The 650-plus infected nodes represent a massive surveillance infrastructure built on borrowed trust.

😊 If you enjoyed the article share it with your friends and follow us.

#FirewallFalcon #SupplyChain #VPNThreats #LinuxSecurity #Backdoor

@PrivacyNotACrime 🗽 ⌨️ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
21
🔍 Tools for source code search

Open-source intelligence operations increasingly depend on examining publicly available code repositories. Security researchers and penetration testers need efficient methods to discover exposed credentials, API keys, and sensitive configuration files that developers accidentally commit to version control systems.

This guide presents five essential tools designed to streamline the process of searching through GitHub and uncovering potential security exposures.

🔗 Gitrob – Repository history scanner

Gitrob clones repositories and scans their entire commit history to find suspicious files containing secrets. It highlights matches using known patterns for sensitive data like passwords and API keys. Findings display through an intuitive web interface for easy review. Ideal for auditing your own projects or assessing third-party codebases before deployment.

📱 Github Dorks – Automated search queries

This Python utility automates advanced GitHub searches using specialized dork syntax. Users can target specific file types, paths, or keywords without learning complex search operators. The tool gracefully handles API rate limits while exporting results in clean formats. Perfect for rapid reconnaissance during security assessments.

🟪 GitGraber – Real-time credential hunter

gitGraber monitors GitHub continuously for credentials targeting services like AWS, Google, PayPal, Facebook, Twitter, and Stripe. Its predefined patterns reduce false positives while delivering actionable results. Run it in the background for instant alerts when new secrets appear. Essential for incident response and proactive exposure monitoring.

👨‍💻 GitHub Search – Command-line investigation suite

A modular collection of CLI tools for systematic GitHub investigations. Script searches, parse results programmatically, and integrate into larger security pipelines. Supports JSON and CSV output for downstream analysis. Handles authentication tokens securely to prevent accidental exposure during execution.

💧 TheScrapper – Contact information extractor

TheScrapper extracts email addresses and social media accounts from website source code and repositories. Parses HTML, JavaScript, and text files to locate personal identifiers. Useful during reconnaissance to identify contributors or build communication vectors. Respects rate limits to avoid triggering security controls while crawling.

🛡 Protection tips for developers

To prevent your code from leaking sensitive data, implement pre-commit hooks before pushing, rotate API keys regularly, use environment variables instead of hardcoding credentials, and deploy continuous monitoring services like GitGuardian or TruffleHog.

😊 If you enjoyed the article share it with your friends and follow us.

#OSINT #CodeSearch #GitHub #SecurityTools #BugBounty

@PrivacyNotACrime 🗽 ⌨️ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
3
🇷🇺 What is the FIRST.org website

If you work in cybersecurity, particularly in SOC operations, incident response, or vulnerability management, you have probably encountered FIRST. This organization is fundamental to how the global security community collaborates during critical situations.

FIRST stands for Forum of Incident Response and Security Teams. It operates as an international association focused on enabling collaboration and experience sharing between security teams, CSIRTs, CERTs, and PSIRTs worldwide.

➡️ Why FIRST.org matters for professionals

The platform delivers several essential resources that shape industry practices and operational standards.
First and foremost, FIRST develops and maintains the Common Vulnerability Scoring System, commonly known as CVSS. This framework represents one of the most important global standards for measuring vulnerability severity, allowing organizations to prioritize remediation efforts based on consistent risk assessment.

Beyond scoring systems, the site offers comprehensive incident response frameworks. These resources guide teams through identifying, analyzing, and containing security breaches efficiently. For those building or managing CSIRT and PSIRT teams, specialized documentation covers team design, operations, and best practices.

💬 Community and specialization

FIRST functions as a vast network where security practitioners across borders share intelligence and coordinate responses. This collaborative approach proves essential when adversaries operate internationally.

The organization also runs Special Interest Groups focusing on targeted areas like threat intelligence, automation, artificial intelligence security, and evolving CVSS methodologies. These SIGs drive innovation within specific security domains.

👥 Practical advice for security teams

To maximize the value of FIRST resources, integrate CVSS scoring into your vulnerability management workflow from the start.

Participating in regional FIRST conferences helps establish personal connections that prove invaluable during active incidents.

For anyone working in Blue Team operations, SOC analysis, incident response, or vulnerability lifecycle management, FIRST.org deserves a permanent spot in your professional bookmarks.

📃 Official Website:

https://www.first.org/

😊 If you enjoyed the article share it with your friends and follow us.

#Cybersecurity #FIRST #IncidentResponse #CVSS #BlueTeam

@PrivacyNotACrime 🗽 ⌨️ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
32👌1
Buy us a coffee ☕
Has our content helped you today? Buy us a coffee to help us keep this space active, updated, and ad-free. Every contribution counts!

Thank you for your support! 🙏
🦠 Malware detection made accessible with XGBoost

Ever wonder if analyzing suspicious files really requires expensive enterprise tools or deep technical skills? A new open source project proves otherwise. It shows how modern machine learning can bring malware analysis within reach of security enthusiasts and small teams who want to identify threats without breaking the bank.

🔂 A modern approach to an old problem

Called Malware-Detector-XGBoost, this is a web based system that classifies Windows executable files as malicious or benign. Developed by I Ketut Widiyane as a Final Year Project, it uses the XGBoost algorithm to examine Portable Executable metadata. Traditional signature based scanners often miss zero day threats, but this system detects patterns and anomalies in file structures instead, providing a proactive defense layer.

The tech stack combines a Python backend using FastAPI for fast inference with a Next.js frontend that keeps the interface clean and responsive. Users upload files through a simple form, get instant analysis results, and can even download detailed PDF reports or export their scan history as CSV. The system handles exe, dll, sys, scr, and ocx files, which covers the most common Windows malware vectors.

🔬 Under the hood

Feature extraction happens in the extractor.py module, which pulls PE metadata like header details, section characteristics, and import tables. These features feed into a trained XGBoost model, while predictor.py delivers the binary classification result. It is not magic, just solid machine learning applied thoughtfully to a real world security challenge.

User management includes two roles: regular users and admins. Regular accounts let you register, upload files, and review your scan history. Admins access global statistics and can manage other users through a dedicated dashboard. This multi user setup works well for universities or security labs that want to share one analysis tool across a team.

🔬 Setting up your own detection lab

You will need Python, Node.js, and MySQL to get started. The documentation walks you through cloning the repo, configuring database credentials in the environment files, and spinning up both backend and frontend services.

Once everything is running, the backend offers a complete API for authentication, file uploads, and analytics, plus interactive docs to explore endpoints.
Running locally means files never leave your infrastructure.

For organizations dealing with sensitive data that cannot go to third party cloud scanners, this privacy preservation is essential.

🧠 Smart security practices to complement detection tools

Having a detection tool helps, but layered security matters more. Keep your operating system and antivirus definitions current to catch what automated tools might miss. Download executables only from verified sources since highly obfuscated malware can fool even advanced detectors. Test suspicious files in isolated virtual machines before touching your main system to avoid accidental compromise. Watch your network traffic too, because some malware communicates externally even when static analysis passes it.

🐱 Check the tool at GitHub

😊 If you enjoyed the article share it with your friends and follow us.

#MachineLearning #CyberSecurity #OpenSource #MalwareAnalysis #TechTools

@PrivacyNotACrime 🗽 ⌨️ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
👌5✍3👀221
🛜 Check your router for hidden vulnerabilities

Think your home network is secure just because you set a strong Wi-Fi password? Maybe not. The router itself, the brain of your connection, might be running outdated firmware with known security holes that hackers can exploit silently. A new open-source project is here to help you discover exactly which risks are lurking behind your gateway.

🚨 A practical tool for proactive defense

Security researcher Mikhail Artamonov has released router-cve-audit, a utility designed to scan your router's firmware and cross-reference it against a massive database of known Common Vulnerabilities and Exposures. Unlike generic scanners, this tool focuses specifically on identifying whether your device is running versions vulnerable to publicly documented exploits, giving you a clear picture of your exposure without requiring deep technical expertise.

The project leverages the growing transparency of vulnerability databases to empower regular users. By analyzing the firmware version and model of your router, it can instantly flag issues ranging from remote code execution flaws to weak default credentials that haven't been patched in years. This matters because many routers sit untouched for months or even years, becoming easy targets for botnets and unauthorized access.

🧐 Why this matters for your privacy

Routers often represent the weakest link in home cybersecurity. A compromised router can lead to traffic interception, DNS hijacking, or even full control over your connected devices. With thousands of CVEs affecting popular brands like TP-Link, ASUS, Netgear, and others, assuming it works fine is no longer sufficient. This audit tool bridges the gap between complex security data and actionable insights for everyday users.

🌟 How to protect yourself

Start by downloading the tool from the official repository and running a quick scan against your router's firmware details. If vulnerabilities surface, update your router's firmware immediately using the latest version from the manufacturer.

If no updates exist for your specific model, seriously consider replacing it with a newer device that receives regular security patches.

For advanced users, enabling automatic updates if available, disabling remote management features, and changing default admin credentials remain essential habits. If you suspect compromise, perform a factory reset followed by a firmware flash where possible.

🐱 Check this awesome tool at GitHub

👍 If you enjoyed the article share it with your friends and follow us.

#RouterSecurity #CVEAudit #NetworkPrivacy #FirmwareUpdate #OpenSource

@PrivacyNotACrime 🗽 ⌨️ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
👌7👀5✍21
💻 Windows 0-day exploited by Lazarus to gain SYSTEM privileges

A newly discovered zero-day vulnerability in Windows has been weaponized by the North Korean hacking group Lazarus as part of their ongoing Operation Dream Job campaign. This sophisticated threat targets defense and aviation sector employees with enticing job offers, only to infect their systems through fake PDF viewer software.

🗡 The mechanics of the attack

At the heart of this operation lies CVE-2026-68820, a previously unknown vulnerability in the Windows Ancillary Function Driver (AFD.sys) with a severity rating of 7.0. This flaw allows attackers to escalate privileges directly to the highest system level, SYSTEM, granting them complete control over the compromised machine.

Microsoft acknowledged the issue on July 31 and released a patch on August 11 as part of their scheduled security updates.

The latest iteration of this campaign involves victims being lured to install a counterfeit application called SecurityPDF, distributed through fraudulent websites impersonating the legitimate company Enveil. Once a specially crafted document is opened within this fake viewer, a new backdoor named Troy is deployed. This malicious tool supports 17 distinct commands, enabling extensive remote control capabilities.

😃 Why continuing with Windows or MacOS may be a mistake

Individuals and organizations that continue relying on Windows or MacOS as primary work tools are increasingly making a risky choice. The reality is stark. Windows vulnerabilities show no signs of ending. Some security experts argue that certain flaws are intentionally embedded to enable law enforcement investigative capabilities, yet these same backdoors inevitably become weapons for cybercriminals once discovered or leaked.

Companies still tied to proprietary operating systems face an endless cycle of patches and emergency fixes.

Meanwhile, open-source alternatives like Linux offer transparency and community-driven security audits that significantly reduce hidden vulnerabilities. For privacy-focused users and businesses handling sensitive data, migrating to Linux is not just advisable. It is becoming essential for long-term digital sovereignty.

💡 Practical migration path to Linux

Transitioning does not mean abandoning your workflow entirely. Many professional applications have Linux-compatible alternatives or run through containers. Start with a dual-boot setup to test compatibility with your daily tools. Distributions like Ubuntu, Fedora, or Debian provide enterprise-grade stability while maintaining full control over your system.

😊 If you enjoyed the article share it with your friends and follow us.

#LazarusGroup #ZeroDay #WindowsSecurity #LinuxMigration #DigitalSovereignty

@PrivacyNotACrime 🗽 ⌨️ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
✍9👀7😁3🤔3👌31
🎮 Twitch using streams to train Amazon AI by default

Are your Twitch broadcasts truly private? Unfortunately, they are not. Your face, voice, chat interactions, clips, and content are currently feeding Amazon's artificial intelligence systems without your knowledge. This process runs silently in the background, enabled automatically from day one.

💵 Default opt-out reveals troubling priorities

Amazon and Twitch explained their reasoning quite bluntly: if participation required active consent, virtually nobody would agree. This straightforward admission shows how creator privacy ranks below data collection objectives. The platform's documentation confirms that user content trains models capable of generating text, audio, images, and video.

🔎 What data is vulnerable

Without manual intervention, Amazon accesses your entire footprint on the platform. Live broadcasts, archived videos, fan-made clips, and real-time chat messages all become potential training material.
Every image and word displayed on your channel enters this extensive pool, turning personal broadcasts into corporate assets without asking permission.

❓ Uncertainty about past harvesting

Questions about previously collected data receive no clear answers. When asked whether specific content had already been used, Twitch leadership admitted they could not confirm what Amazon processed historically. Statements from 2024 acknowledged Amazon was pulling Twitch content for AI purposes, yet creators stay uninformed about how much has disappeared into training systems. Once absorbed into these pipelines, removing your data becomes practically impossible.

🛡 Protecting yourself step by step

You can stop future data collection through simple settings adjustments. Navigate to your profile picture → settings → security and privacy. Scroll down until you find the "Generative AI Training" option and turn it off completely. Pay attention because some users report this switch toggling back on unexpectedly, demanding regular checks.

Two important caveats deserve attention. Opting out protects only your own channel content. When you join chat rooms on other streamers' broadcasts, their settings control your visibility regardless of your preferences. Furthermore, this action prevents only incoming training sessions. No mechanism exists to recover or identify what has already been consumed by Amazon's systems.

😊 If you enjoyed the article share it with your friends and follow us.

#TwitchAI #DataPrivacy #CreatorRights #AmazonAI #DigitalSecurity

@PrivacyNotACrime 🗽 ⌨️ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
✍7👌4👀2🤷‍♂1😁1🤔11
🤖 Strix brings AI-powered pentesting to open source

Think penetration testing requires weeks of manual work and expensive security consultants? Strix challenges that assumption by combining artificial intelligence with the same offensive security tools professional ethical hackers use.

This open-source platform empowers developers and security teams to identify and fix vulnerabilities faster than traditional methods allow.

⚙️ Agentic pentesting meets real-world tools

Strix agents deploy a comprehensive security toolkit directly into your development workflow. From HTTP interception proxies with full request manipulation to automated browser exploitation for XSS and CSRF testing, the platform mirrors what human pentesters accomplish manually. The shell execution environment enables interactive exploit development while the custom Python sandbox validates proof-of-concept exploits safely. Reconnaissance capabilities automatically map attack surfaces through subdomain enumeration and fingerprinting without human intervention.

📎 Static analysis finally catches context

Unlike conventional scanners drowning teams in false positives, Strix combines SAST and DAST capabilities with vulnerability intelligence. Each finding includes CVSS scoring and OWASP classification with structured details and reproduction steps. The dashboard displays live agent activity, severity breakdowns, and allows mid-scan steering instructions through the browser interface. Teams can browse historical runs and generate shareable reports emailed directly to stakeholders.

🌏 Enterprise features without vendor lock-in

The platform scales from individual developers to organizations needing compliance-ready documentation. SOC 2, ISO 27001, and PCI DSS reporting comes standard alongside SSO integration via SAML or OIDC.

Custom deployment options include VPC hosting and self-hosted configurations with bring-your-own-key model support. Security teams maintain full control while benefiting from dedicated SLA-backed support channels.

🐱 Check this tool at GitHub

😊 If you enjoyed the article share it with your friends and follow us.

#AIsecurity #Pentesting #DevSecOps #OpenSource #AppSec

@PrivacyNotACrime 🗽 ⌨️ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
👀8👌5✍3😁21
This media is not supported in your browser
VIEW IN TELEGRAM
📸 FLOCK: The AI surveillance network watching America

A private company based in Atlanta has quietly built one of the most expansive surveillance networks ever seen on US soil. Flock Safety, founded in 2017, has deployed roughly 120,000 automated license plate reader cameras across 49 states, capturing vehicle data in real time and building a permanent record of citizen movement.

Marketed as a public safety tool, the system has sparked fierce opposition from privacy advocates and civil liberties organizations who warn that it effectively eliminates anonymity in public spaces.

⚙️ How FLOCK cameras operate

These devices are self-contained units powered by solar panels or LTE connections, mounted on traffic poles, lampposts, and other public fixtures. Each camera captures not only license plates but also vehicle make, model, color, and what the company calls a "vehicle signature." The AI processes this data instantly and cross-references it against databases of stolen vehicles, Amber Alerts, and custom watchlists created by local law enforcement.

What makes this particularly alarming is the retroactive search capability. Officers can look back weeks or even months to reconstruct the movement history of any vehicle, without needing prior suspicion of a crime. This turns ordinary traffic into a searchable database of human behavior, where every trip to the store, a doctor's appointment, or a protest becomes a data point permanently stored and queryable by more than 5,000 law enforcement agencies nationwide.

🚨 Threats to privacy and civil liberties

The ACLU and other organizations have raised serious concerns about the indefinite storage of data belonging to innocent citizens. Reports have emerged of this information being accessed by federal agencies such as ICE for immigration enforcement, expanding the system's reach far beyond its original public safety purpose.

Without federal regulation, data retention policies vary wildly between jurisdictions. Some areas keep records indefinitely, creating an ever-growing database of personal movement patterns. Critics have drawn parallels to dystopian literature, noting that constant surveillance produces a chilling effect on free speech and peaceful assembly. People have reportedly avoided attending protests, political meetings, or medical facilities out of fear of being tracked and catalogued.

There are also documented cases of security vulnerabilities. Researcher Benn Jordan discovered that some Flock cameras were left live-streaming to the open internet, and that company executives had accessed live feeds from cameras near schools and gymnastics facilities. The company's CEO even sent emails to police department customers claiming that Flock and law enforcement were "under attack" by YouTube videos exposing these issues.

🌐 Practical steps to reduce your exposure

While completely avoiding cameras in urban environments is nearly impossible, there are meaningful actions you can take. Community mapping tools like DeFlock allow you to identify known ALPR locations near you and plan routes that minimize exposure. Supporting local legislation that limits data retention periods and requires warrants for retrospective searches is another powerful way to push back. Organizations like the EFF and ACLU actively monitor surveillance deployments and provide resources for community advocacy. You can also demand transparency from your local government regarding contracts with surveillance companies and how your data is handled.

🔍 Find where cameras are installed near you:

https://deflock.org
https://maps.deflock.org

😊 If you enjoyed the article share it with your friends and follow us.

#MassSurveillance #PrivacyRights #FlockSafety #CivilLiberties #ALPR

@PrivacyNotACrime 🗽 ⌨️ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
👀6🤔4✍3👌2😁1
🤖 Nodriver: Advanced automation and web scraping

Collecting web data today means dealing with serious anti-bot defenses. That's where nodriver comes in. As the successor to Undetected-Chromedriver, this library handles asynchronous web automation and scraping while slipping past detection systems like Captcha and CloudFlare. For developers who need reliable access to web data, it's built to work when other tools fail.

🖥 Core features and ease of use

Unlike Selenium-heavy solutions, nodriver runs light and fast. You can start a browser session with literally one line of code. Each execution automatically cleans up user profiles afterward, which helps avoid fingerprinting issues. The element search and selection methods are also more advanced than what you get with traditional libraries, saving time on complex interactions.

▶️ Performance and resilience benefits

Speed is noticeably better thanks to the async architecture. Data collection happens faster, but the real win is how it holds up against WAFs and bot mitigation systems. I've seen scrapers that normally block within minutes keep running for hours with nodriver. For both quick prototypes and production setups, that reliability makes a difference.

👨‍💻 Ideal use cases

If your project involves scraping sites known for blocking automation, or you need to navigate flows that aggressively detect bots, this tool gives you the flexibility to stay under the radar. It's particularly useful when you're tired of constantly tweaking scripts just to get through basic pages.

🛡 Protection tips for ethical scraping

Powerful tools come with responsibility. Here's how to use them without causing issues:

▫️ Check robots.txt first — respect what sites allow you to scrape.

▫️ Add delays between requests so servers don't get overwhelmed.

▫️ Read Terms of Service before automating access to any site.

▫️ Watch out for personal data — GDPR and similar regulations still apply.

🐱 For those wanting to dive into the code or documentation, check out the official repository

😊 If you enjoyed the article share it with your friends and follow us.

#Python #WebScraping #Automation #CyberSecurity #OpenSource

@PrivacyNotACrime 🗽 ⌨️ Chat
Please open Telegram to view this post
VIEW IN TELEGRAM
✍6👌5😁2🤔1👀111